Dental Clinic Appointment Reservation System is an online system which allows all patients a way to schedule an appointment.
Dental Clinic Appointment Reservation System is vulnerable to SQL injection.
A remote authenticated attacker could send specially crafted UNION SQL statements to the admin/sort_date.php script using the 'date' parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.
PAYLOAD - date=' UNION SELECT NULL,NULL,@@version,username,password,NULL FROM users -- -&sort=
By turning this into a traffic file and matching rule, we are able to detect attempts to influence the vulnerable parameter with SQL injections.
Idappcom has created signature 8021318 along with a traffic file.
If you are concerned that your business may be at risk of this vulnerability or others why not try out our Traffic IQ software which can share your defences and report any issues. Learn more here: https://www.idappcom.co.uk/traffic-iq-professional